Outer VXLAN Header
Starting with release 21.1.1.0, Extreme 9920 software
supports outer VXLAN headers. The VXLAN filters can be enabled per port.
The
VXLAN frames can be filtered based on VNID, IPv4 source
address, and IPv4 destination address.
- VXLAN
frames that do not match the filter are dropped.
- VXLAN
headers in the matching frames are terminated, and a new SAP is assigned for further
processing.
- VXLAN
packets without outer tag are processed as transport tunnel packets and the VXLAN headers are terminated.
Limitations
The outer VXLAN header limitations are as follows:
- Multiple ingress-groups can share the
same outer VXLAN filter.
- Ingress-groups with the same outer VXLAN filter belong to the same hardware table and share the
counter and mirror actions.
- Multiple ingress-groups configured
without tunnel ID, source IP address, or destination IP address can create conflicts among
ingress-groups.
- The order of priority for ingress frames that match filters from multiple ingress-groups
is as follows:
- Tunnel ID
- Source IP address
- Destination IP address